← Back to browse · API

CVE-2025-49706

Severity
MEDIUM
CVSS
6.5
EPSS
0.99879
Risk score
85.96
CISA KEV
Yes
PoC
No
Published
2025-07-22
Modified
2025-07-22
First seen
2026-08-05
Aliases
EUVD-2025-20552, GHSA-J67G-R75F-8HGP
Products
Microsoft:Microsoft SharePoint Enterprise Server 2016 16.0.0 <16.0.5508.1000, Microsoft:Microsoft SharePoint Server 2019 16.0.0 <16.0.10417.20027, Microsoft:Microsoft SharePoint Server Subscription Edition 16.0.0 <16.0.18526.20424, Microsoft:SharePoint, microsoft:sharepoint_enterprise_server, microsoft:sharepoint_server
Sources
nvd CVE-2025-49706
euvd EUVD-2025-20552
cisa.gov CVE-2025-49706

Description

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.

References